| Exam Name: | EC Council Certified Incident Handler (ECIH v3) | ||
| Exam Code: | 212-89 Dumps | ||
| Vendor: | ECCouncil | Certification: | ECIH |
| Questions: | 356 Q&A's | Shared By: | isra |
Olivia, a cybersecurity responder at a multinational firm, is alerted late at night by the Network Operations Center (NOC) about unusual latency and degraded performance across several critical applications hosted on the company ' s internal servers. Upon initial inspection, she notices that internal routers are experiencing an unusually high volume of ARP requests being broadcast across the network. Network bandwidth utilization has spiked, and multiple routers are reporting elevated CPU usage.
Further diagnostics show that NAT tables on edge routers are saturated with numerous entries from the same IP range within a short period. These entries initiate simultaneous connections to different ports across various endpoints. Firewall logs show repeated attempts to access unused services, while the ISP reports an overflow of incoming requests from numerous geographic locations. The same pattern is occurring across different branches, indicating a coordinated attempt to overwhelm the systems. What should Olivia suspect?
After a recent email attack, Harry is analyzing the incident to obtain important information related to the incident. While investigating the incident, he is trying to
extract information such as sender identity, mail server, sender’s IP address, location, and so on.
Which of the following tools Harry must use to perform this task?
A multinational law firm suffered a sophisticated malware attack that encrypted critical legal documents. During recovery, there is concern that some archived backups may already be compromised. Which recovery-focused action should the organization prioritize to ensure safe restoration?
Elena, a first responder at a multinational firm, receives multiple reports from employees claiming they were asked to update their payroll information through an email that appears to be from HR. The email includes a URL directing users to a login page identical to the company ' s intranet but hosted on an unfamiliar domain. Elena immediately informs the IH & R team, preserves the email headers, captures screenshots of the spoofed page, and blocks the domain at the network level. What type of email security incident is Elena handling?